|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:240335) triggered by 197.186.28.166 (166-28-186-197.r.airtel.co.tz): ...
show more
(mod_security) mod_security (id:240335) triggered by 197.186.28.166 (166-28-186-197.r.airtel.co.tz): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 12 14:50:59.386776 2026] [security2:error] [pid 29026:tid 29052] [client 197.186.28.166:60664] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 197.186.28.166 (+1 hits since last alert)|eceinal.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "eceinal.com"] [uri "/xmlrpc.php"] [unique_id "alPiE8XVAjUX975TW_LIlwAAABg"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:240335) triggered by 197.186.28.166 (166-28-186-197.r.airtel.co.tz): ...
show more
(mod_security) mod_security (id:240335) triggered by 197.186.28.166 (166-28-186-197.r.airtel.co.tz): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 12 14:18:41.680541 2026] [security2:error] [pid 22982:tid 22982] [client 197.186.28.166:50911] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 197.186.28.166 (+1 hits since last alert)|reelvisionboard.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "reelvisionboard.com"] [uri "/xmlrpc.php"] [unique_id "alPagXsDcWI3LQfvUqck8QAAAA0"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
Anonymous
|
|
197.186.28.166 - - [11/Jul/2026:19:48:51 +0200] "POST /xmlrpc.php HTTP/1.1" 200 593 "-" "WordPress.c ...
show more
197.186.28.166 - - [11/Jul/2026:19:48:51 +0200] "POST /xmlrpc.php HTTP/1.1" 200 593 "-" "WordPress.com; https://wordpress.com"
197.186.28.166 - - [11/Jul/2026:19:48:51 +0200] "POST /xmlrpc.php HTTP/1.1" 200 403 "-" "WordPress.com; https://wordpress.com"
197.186.28.166 - - [11/Jul/2026:19:49:00 +0200] "POST /xmlrpc.php HTTP/1.1" 200 593 "-" "Jetpack/13.0; WordPress/6.4; http://site11679516.com"
197.186.28.166 - - [11/Jul/2026:19:49:00 +0200] "POST /xmlrpc.php HTTP/1.1" 200 403 "-" "Jetpack/13.0; WordPress/6.4; http://site11679516.com"
197.186.28.166 - - [11/Jul/2026:19:49:10 +0200] "POST /xmlrpc.php HTTP/1.1" 200 593 "-" "WordPress.com; https://wordpress.com"
...
show less
|
Brute-Force
Web App Attack
|
|
|
๐ซ๐ท
dynamix
|
|
WordPress XMLRPC Brute Force Attack
|
Brute-Force
Web App Attack
|
|
|
๐ฆ๐บ
screwlooseit.com.au
|
|
Blocked by CSF 13 firewall - Rule: XMLRPC
TZ/Tanzania/166-28-186-197.r.airtel.co.tz
|
Web App Attack
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:240335) triggered by 197.186.28.166 (166-28-186-197.r.airtel.co.tz): ...
show more
(mod_security) mod_security (id:240335) triggered by 197.186.28.166 (166-28-186-197.r.airtel.co.tz): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 11 09:48:13.549097 2026] [security2:error] [pid 13231:tid 13231] [client 197.186.28.166:52881] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 197.186.28.166 (+1 hits since last alert)|thepercussionworks.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "thepercussionworks.com"] [uri "/xmlrpc.php"] [unique_id "alJJnbrmGN62EtaH7lEbIQAAABM"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
Anonymous
|
|
[redacted] 197.186.28.166 - - [11/Jul/2026:14:13:18 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" " ...
show more
[redacted] 197.186.28.166 - - [11/Jul/2026:14:13:18 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com"
[redacted] 197.186.28.166 - - [11/Jul/2026:14:13:25 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "WordPress.com; https://wordpress.com"
[redacted] 197.186.28.166 - - [11/Jul/2026:14:13:36 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com (Jetpack 12.1; WordPress 6.2)"
[redacted] 197.186.28.166 - - [11/Jul/2026:14:13:47 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com"
[redacted] 197.186.28.166 - - [11/Jul/2026:14:13:57 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com (Jetpack 13.0; WordPress 6.1)"
...
show less
|
Hacking
Web App Attack
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:240335) triggered by 197.186.28.166 (166-28-186-197.r.airtel.co.tz): ...
show more
(mod_security) mod_security (id:240335) triggered by 197.186.28.166 (166-28-186-197.r.airtel.co.tz): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 22 11:12:35.371553 2026] [security2:error] [pid 12161:tid 12161] [client 197.186.28.166:61460] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 197.186.28.166 (+1 hits since last alert)|monogay.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "monogay.org"] [uri "/xmlrpc.php"] [unique_id "ajlQ40-7xckOZsp9MCODCQAAABU"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
Anonymous
|
|
Unauthorized connection attempt on Port 2323
|
Port Scan
Hacking
Exploited Host
|
|
|
๐ฉ๐ช
bescared
|
|
F2B - Malicious activity detected. Unauthorized connection attempt: Telnet.
|
Port Scan
|
|
|
๐ฆ๐น
begou.dev
|
|
[Threat Intelligence] Port Scanning and/or Unauthorized access -> TCP/23
|
Port Scan
|
|